SUSE Security Update: Security update for OpenSSL
______________________________________________________________________________

Announcement ID:    SUSE-SU-2014:0768-1
Rating:             critical
References:         #459468 #489641 #880891 
Cross-References:   CVE-2011-4354 CVE-2014-0224
Affected Products:
                    SUSE CORE 9
______________________________________________________________________________

   An update that solves two vulnerabilities and has one
   errata is now available.

Description:


   OpenSSL was updated to fix the following security vulnerabilities:

       * SSL/TLS MITM vulnerability. (CVE-2014-0224)
       * ECC private key can leak on 32 bit platforms. (CVE-2011-4354)

   Further information can be found at
       .

   Security Issues references:

       * CVE-2014-0224
         
       * CVE-2011-4354
         



Package List:

   - SUSE CORE 9 (i586 s390 s390x x86_64):

      openssl-0.9.7d-15.50
      openssl-devel-0.9.7d-15.50
      openssl-doc-0.9.7d-15.50

   - SUSE CORE 9 (x86_64):

      openssl-32bit-9-201406041231
      openssl-devel-32bit-9-201406041231

   - SUSE CORE 9 (s390x):

      openssl-32bit-9-201406060130
      openssl-devel-32bit-9-201406060130


References:

   https://www.suse.com/security/cve/CVE-2011-4354.html
   https://www.suse.com/security/cve/CVE-2014-0224.html
   https://bugzilla.novell.com/459468
   https://bugzilla.novell.com/489641
   https://bugzilla.novell.com/880891
   https://scc.suse.com:443/patches/

SuSE: 2014:0768-1: critical: OpenSSL

June 7, 2014
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

OpenSSL was updated to fix the following security vulnerabilities: * SSL/TLS MITM vulnerability. (CVE-2014-0224) * ECC private key can leak on 32 bit platforms. (CVE-2011-4354) Further information can be found at . Security Issues references: * CVE-2014-0224 * CVE-2011-4354 Package List: - SUSE CORE 9 (i586 s390 s390x x86_64): openssl-0.9.7d-15.50 openssl-devel-0.9.7d-15.50 openssl-doc-0.9.7d-15.50 - SUSE CORE 9 (x86_64): openssl-32bit-9-201406041231 openssl-devel-32bit-9-201406041231 - SUSE CORE 9 (s390x): openssl-32bit-9-201406060130 openssl-devel-32bit-9-201406060130

References

#459468 #489641 #880891

Cross- CVE-2011-4354 CVE-2014-0224

Affected Products:

SUSE CORE 9

https://www.suse.com/security/cve/CVE-2011-4354.html

https://www.suse.com/security/cve/CVE-2014-0224.html

https://bugzilla.novell.com/459468

https://bugzilla.novell.com/489641

https://bugzilla.novell.com/880891

https://scc.suse.com:443/patches/

Severity
Announcement ID: SUSE-SU-2014:0768-1
Rating: critical

Related News